3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4368
WP CSV Web Windows
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

The WP CSV WordPress plugin through 1.8.0.0 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, and doe snot have CSRF checks in place as well, leading to a Reflected Cross-Site Scripting.

CVE-2022-46088
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 2 PoCs

Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.

CVE-2022-33322
Air Conditioning MSZ-FD40/56/63/71/8022S Web
6.1
MEDIUM
EPSS
1.5%
2022 CWE-79 1 PoC

Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected prod

CVE-2022-36223
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2022 1 PoC

In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.

CVE-2022-0764
strapi/strapi Web
6.1
MEDIUM
EPSS
0.2%
2022 CWE-78 1 PoC

Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

CVE-2022-1254
Secure Web Gateway Web
6.1
MEDIUM
EPSS
0.2%
2022 CWE-601 1 PoC

A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicious website controlled by the attacker. This is possible because SWG incorrectly creates a HTTP redirect response when a user clicks a carefully constructed URL. Following the redirect response, the new request is still filtered by the SWG policy.

CVE-2022-2015
jgraph/drawio Web
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.

CVE-2022-38467
CRM Perks Forms – WordPress Form Builder Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
17.7%
2022 CWE-79 0 PoCs

Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.

CVE-2022-0421
Five Star Restaurant Reservations Web Windows
6.1
MEDIUM
EPSS
1.0%
2022 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments

CVE-2022-20959
Cisco Identity Services Engine Software Web Networking
6.1
MEDIUM
EPSS
0.2%
2022 CWE-79 2 PoCs

A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by persuading an authenticated administrator of the web-based management interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access

CVE-2022-41376
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2022 1 PoC

Metro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.

CVE-2022-40912
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2022 1 PoC

ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter 'action' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.

CVE-2022-40088
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2022 3 PoCs

Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.

CVE-2022-4301
Sunshine Photo Cart Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
3.9%
2022 1 PoC

The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2022-31596
SAP Business Objects Platform (Monitoring DB) Web
6.0
MEDIUM
EPSS
0.3%
2022 CWE-668 1 PoC

Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjects Business Intelligence Platform (Monitoring DB) - version 430, can access BOE Monitoring database to retrieve and modify (non-personal) system data which would otherwise be restricted. Also, a potential attack could be used to leave the CMS's scope and impact the database. A successful attack could have a low impact on confidentiality, a high impact on integrity, and a low impact on availability.

CVE-2022-21575
WebCenter Sites Web Database
6.0
MEDIUM
EPSS
0.5%
2022 1 PoC

Vulnerability in the Oracle WebCenter Sites Support Tools product of Oracle Fusion Middleware (component: User Interface). The supported version that is affected is Prior to 4.4.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites Support Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites Support Tools accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites Support Tool

CVE-2022-4605
flatpressblog/flatpress Web
6.0
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2022-3035
snipe/snipe-it Web
5.9
MEDIUM
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.

CVE-2022-22405
Aspera Faspex Web
5.9
MEDIUM
EPSS
0.0%
2022 CWE-311 1 PoC

IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 222576.

CVE-2022-21473
Banking Treasury Management Web Database
5.9
MEDIUM
EPSS
0.4%
2022 1 PoC

Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Treasury Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data as